VYPR
High severity8.1NVD Advisory· Published Feb 12, 2021· Updated Jun 17, 2026

CVE-2021-27197

CVE-2021-27197

Description

DSUtility.dll in Pelco Digital Sentry Server before 7.19.67 has an arbitrary file write vulnerability. The AppendToTextFile method doesn't check if it's being called from the application or from a malicious user. The vulnerability is triggered when a remote attacker crafts an HTML page (e.g., with "OBJECT classid=" and "") to overwrite arbitrary files.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Pelco/Digital Sentry Serverllm-fuzzy2 versions
    <7.19.67+ 1 more
    • (no CPE)range: <7.19.67
    • cpe:2.3:a:pelco:digital_sentry_server:*:*:*:*:*:*:*:*range: <7.19.67
  • Range: <7.19.67
  • Pelco/Digital Sentry Serverdescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.